Skip to content
Centrelink warning as 270,000 emails sent out in attack related to Medicare, superannuation ...

Centrelink warning as 270,000 emails sent out in attack related to Medicare, superannuation ...

Au.Finance.Yahoo November 18, 2025

Australians are being bombarded with tens of thousands of fake emails impersonating Centrelink and Services Australia in one of the biggest phishing campaigns in years. Cybercriminals are using artificial intelligence to create “super clones” of legitimate messages, making them increasingly difficult to spot.

More than 270,000 of the malicious emails have been detected in the past four months by human risk management platform Mimecast. The emails mimic legitimate communications and leverage information benefits like superannuation , JobSeeker payments, Medicare and Family Tax Benefits.

Mimecast senior director of solutions engineering Garrett O’Hara told Yahoo Finance it was one of the "biggest" phishing campaigns the group had seen in the past three years.

Centrelink cancellation warning as letters sent out over $663 fortnightly payment: 'It's time'

Baby boomers urged to rethink $4.9 trillion Gen Z inheritance trend

Aussie tradie reveals lucrative salary for in-demand job he says ‘anyone can do’

“It’s not targeted at any specific organisation, which we do see sometimes. It’s really quite a broad attack and honestly an attack on fairly vulnerable people when you think the services involved here, which is kind of sickening,” he said.

While it's unclear the degree to which AI is being used, O’Hara said the convincing and large scale nature of the scam meant it was almost certainly playing a part.

“If you start to look at the phishing scams that are coming through now they’re actually very excellent. They’re so, so convincing and that’s no accident,” he said.

“You remember the advice to look for grammar that’s wonky or syntax, that’s all gone … [We’re] seeing a perfectly written email, really in any language, with good syntax and perfect grammar and exactly the same layout as the real deal – that’s trivial to do with AI.”

Do you have a story to ? tamika.seeto@yahooinc.com

In some cases, scammers can go a step further by compromising real email accounts and hosting fake government login pages on legitimate web services, making them even harder to detect.

Once you click a link and enter your details, attackers are able to gain access to your personal or business accounts, which can lead to data theft, malware installation, or ransomware infections.

O’Hara said there were major consequences potentially at stake, including identity theft .

“A lot of people, unfortunately, they still use the same email address and passwords for lots of different services,” he said.

“If you’re doing that and you’re getting compromised as part of this attack, there’s a thing called credential stuffing where they take the credentials they’ve stolen in a attack and then they just try different platforms.”

Extracted Entities

Countries (1)

Domains (1)

Industries (1)